7.5
CVE-2013-4182
- EPSS 2.4%
- Veröffentlicht 16.09.2013 19:14:38
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Theforeman ≫ Foreman Version <= 1.2.1
Theforeman ≫ Foreman Version 1.2.0
Theforeman ≫ Foreman Version 1.2.0 Update rc1
Theforeman ≫ Foreman Version 1.2.0 Update rc2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.4% | 0.818 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://rhn.redhat.com/errata/RHSA-2013-1196.html
http://theforeman.org/manuals/1.2/index.html#Releasenotesfor1.2.2
http://projects.theforeman.org/issues/2863
https://bugzilla.redhat.com/show_bug.cgi?id=990374